Improper Authentication in Parse Server - #VU149933
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to spoof an external identity and pre-hijack accounts.
The vulnerability exists due to improper authentication in Parse Server's code-based authentication adapters when authentication data is supplied with a username and password to the login endpoint. A remote user can attach an arbitrary unverified provider identity to their own account to spoof an external identity and pre-hijack accounts.
Only deployments configured with an affected code-based authentication adapter are vulnerable.